Data Processing Agreement

Last updated: August 31, 2026; version 1.1 effective October 1, 2026(see previous version)

This document is published in French and in English. In case of any discrepancy between the two versions, the French version prevails.

1. Introduction and scope

This Data Processing Agreement (hereinafter the “ETD” or “DPA”) is an addendum to the Meo Terms of Use (the “Terms”) entered into between 9553-6785 Québec Inc., a company incorporated under the laws of Quebec, which operates the Meo document management software (hereinafter “Meo” or “we”), and the entity that accepted the Terms (hereinafter the “Client”).

This DPA applies when Meo processes Personal Information on behalf of the Client in the course of providing the Services. It establishes the parties' commitments concerning that processing under the Applicable Privacy Laws, without transferring responsibility for the Client's own legal obligations to Meo.

In the event of a conflict between this DPA and the Terms, this DPA prevails with respect to the processing of Personal Information.

2. Definitions

“Competent Privacy Authority”

Any public authority responsible for enforcing the Applicable Privacy Laws governing the relevant processing.

“Client Data”

All data, including Personal Information, submitted, stored, sent or received by the Client, its authorized users or its external collaborators in the course of using the Services.

“Privacy Incident”

Any unauthorized access to, use or disclosure of Personal Information, as well as any loss of Personal Information or other breach of its protection.

“Applicable Privacy Laws”

The privacy and data protection laws and regulations that apply to either party's processing in connection with the Services.

“Personal Information”

Any information about an identifiable individual that is protected by the Applicable Privacy Laws.

“Privacy Officer”

The person designated by an organization to oversee its privacy practices under the Applicable Privacy Laws.

“Services”

The Meo document management software, including the client portal, the document collection features, secure storage, and any related service provided under the Terms.

“Subsequent Vendor”

Any third party authorized by Meo to process Client Data on behalf of the Client in the course of providing the Services.

3. Roles of the parties

For the purposes of this DPA, the parties acknowledge that:

a)

The Client remains the organization responsible for the Personal Information it collects and controls and for meeting its own obligations under the Applicable Privacy Laws.

b)

Meo acts as a service provider and processes Client Data only on the Client's behalf, in accordance with its instructions and to provide the Services.

c)

This DPA records the Client's instructions and the safeguards governing Meo's processing of Client Data.

4. Description of the processing

4.1 Object and purpose: Meo processes Client Data only for the following purposes: secure document storage, management of document requests and client portals, encryption, backup, access logging, and any feature inherent to the Services as described in the Terms.

4.2 Categories of individuals concerned: The individuals whose Personal Information may be processed include:

  • The Client's clients
  • The Client's employees
  • The Client's external collaborators
  • Any natural person whose information appears in the documents uploaded to Meo

4.3 Types of personal information: The types of information that may be processed include, without limitation:

  • Names, addresses, telephone numbers, email addresses
  • Identification numbers
  • Financial and tax information
  • Any other personal information contained in the documents uploaded by the Client

4.4 Duration of the processing: Processing starts on the date the Client's account is activated and ends in accordance with section 12 of this DPA.

5. Meo's obligations

Under this DPA and the Applicable Privacy Laws, Meo makes the following commitments:

5.1 Purpose limitation: Meo processes Client Data exclusively in the performance of this contract for services and for the provision of the Services.

Meo expressly undertakes not to use Client Data for the purposes of:

  • Advertising, profiling or marketing
  • Training artificial intelligence models
  • Analysis of aggregated or disaggregated data for commercial purposes
  • Any other purpose not expressly provided for in the Terms or in this DPA

5.2 Confidentiality protection measures: Meo implements and maintains the following technical and organizational measures:

Encryption

  • In transit: TLS 1.3 for all communications
  • At rest: AES-256 for all Client Data

Access control

  • Principle of least privilege
  • Multi-factor authentication mandatory in production
  • Access to document contents limited to authorized personnel and necessary circumstances

Hosting in Canada

  • Customer-managed documents and primary application data stored in Canada in the AWS Canada (Central) region (ca-central-1)
  • No customer-managed document stored outside Canada; some vendors process limited information elsewhere

Document integrity

  • SHA-256 fingerprint on upload
  • Audit log of key actions

5.2.5 Organizational security: All Meo personnel are bound by contractual confidentiality obligations. Meo is preparing its controls for a SOC 2 Type 2 examination. A Cloudflare web application firewall (WAF) is in place to protect against threats.

5.3 Personnel confidentiality: Meo ensures that every person authorized to process Client Data is subject to a contractual confidentiality obligation and has received adequate training on the protection of personal information.

5.4 Default privacy settings

Meo configures the default privacy settings of the Services to limit access to and disclosure of Client Data unless the Client chooses to change them.

6. Notification of privacy incidents

Meo will notify the Client's Privacy Officer without undue delay after becoming aware of a Privacy Incident or a violation or attempted violation of its confidentiality obligations involving Client Data, and within any shorter period required by the Applicable Privacy Laws.

6.1 Content of the notification: The notification will include, to the extent the information is available:

  • The nature of the Privacy Incident
  • The categories and approximate number of individuals concerned
  • A description of the Personal Information involved
  • An assessment of the risk of injury to the individuals concerned
  • The measures taken or contemplated to mitigate the consequences

6.2 Cooperation: Meo will provide reasonable cooperation to help the Client meet its own notification obligations towards the Competent Privacy Authority and the individuals concerned.

6.3 Incident records: Meo keeps the incident records required by the Applicable Privacy Laws for the required period.

7. Right of verification

Meo allows the Client's Privacy Officer to carry out a verification relating to the observance of the confidentiality obligations set out in this DPA, subject to the procedure below.

7.1 Procedure

  • The Client may request, once (1) per twelve (12) month period, a verification of Meo's compliance with the obligations of this DPA.
  • The request must be made in writing, with reasonable advance notice of at least thirty (30) days.
  • The verification may take the form of a written questionnaire, a documentary review, or an audit conducted by an independent third party chosen by mutual agreement.
  • Meo will make its SOC 2 reports available to the Client when they become available, along with its penetration test reports and any other relevant documentation.

7.2 Confidentiality of the results: The results of any verification are treated as confidential information of Meo and may not be disclosed to third parties without Meo's written consent, unless the law requires it.

8. Subsequent Vendors

8.1 General authorization: The Client authorizes Meo to use the Subsequent Vendors listed below for the provision of the Services.

8.2 Meo's obligations towards its vendors: Before entrusting the processing of Client Data to a Subsequent Vendor, Meo makes sure that:

  • A written contract imposes protection obligations appropriate to the processing entrusted to the vendor
  • Contractual and other measures are intended to provide a comparable level of protection during processing, in accordance with the Applicable Privacy Laws
  • Meo remains fully liable to the Client for the acts and omissions of its Subsequent Vendors

8.3 Notice of change: Meo will inform the Client by email at least thirty (30) days before authorizing a new Subsequent Vendor to process Client Data. The Client may object in writing within that period. If a reasonable objection is left unresolved, the Client may terminate the affected Services.

8.4 List of current vendors

Vendor Location Function Data processed
AWS (ca-central-1) Canada (Central) Hosting and storage Documents, account data, metadata
Supabase Montréal, QC Database and auth. Account data, authentication, files
Stripe United States Payments Billing data (not stored by Meo)
Postmark United States Transactional emails Name, email, notification content
Cloudflare Global (transit) Security and CDN Data in transit only (TLS 1.3)

The list above is the current list of Subsequent Vendors authorized to process Client Data under this DPA.

9. Cross-border transfers

Customer-managed documents and primary application data are stored in Canada, in the AWS Canada (Central) region (ca-central-1). No customer-managed document is stored outside Canada; some vendors may process limited information elsewhere.

Some Subsequent Vendors, including Stripe, Postmark and Cloudflare, may process limited Personal Information outside Canada. For those transfers:

  • Data processing agreements are in place with each Subsequent Vendor
  • Contractual and security measures appropriate to the processing and the Applicable Privacy Laws govern each transfer
  • Meo provides the Client with the information reasonably needed to conduct any privacy assessment required by the Applicable Privacy Laws

On request, Meo makes reasonably available documentation about its security measures and those of its Subsequent Vendors to support the Client's privacy assessments.

10. Requests from individuals

Meo provides tools and reasonable assistance to help the Client respond to requests from individuals under the Applicable Privacy Laws:

Request type Tools available in Meo
Access and export One-click export of the client's data from the dashboard
Rectification Tools to edit and update data
Deletion and anonymization One-click anonymization, deletion from active systems and scheduled backup purge
Structured formats Export in structured formats: CSV, JSON, XML
Publication and indexing Meo neither publishes nor indexes Client Data

The Client remains responsible for responding to requests from the individuals concerned within the time limits prescribed by the Applicable Privacy Laws.

11. Cooperation on privacy assessments

Meo cooperates with the Client in carrying out privacy assessments required by the Applicable Privacy Laws by providing:

  • The technical security documentation for the Services
  • Information on the location of the processing and on the Subsequent Vendors
  • The available assurance and security assessment reports (SOC 2, penetration tests)
  • Any other reasonably necessary information

12. Return and destruction of data

Subject to the retrieval and deletion periods below and the requirements of the Applicable Privacy Laws, Meo will not retain Client Data after the expiry or termination of the Terms.

12.1 Retrieval period

For a period of thirty (30) days following the end of the contract, the Client can download all of its Client Data from its dashboard.

12.2 Destruction

After the retrieval period:

  • Client Data in production will be deleted within sixty (60) days
  • Backup copies will be purged within ninety (90) days
  • On request, Meo will provide written confirmation of the destruction

12.3 Exceptions

Meo may keep Personal Information beyond the periods above only to the extent required by the Applicable Privacy Laws, for example for billing documents retained for tax purposes.

13. Client obligations

The Client undertakes to:

  • Designate a Privacy Officer where required by the Applicable Privacy Laws and provide Meo with their contact details
  • Make sure that the Personal Information transmitted to Meo was collected in accordance with the Applicable Privacy Laws, including obtaining necessary consents where required
  • Carry out privacy assessments required by the Applicable Privacy Laws
  • Respond to requests from the individuals concerned within the time limits prescribed by the Applicable Privacy Laws

14. Liability

Each party's liability under this DPA is subject to the limitations and exclusions of liability set out in the Terms, unless the Applicable Privacy Laws provide otherwise.

Meo remains liable for the acts and omissions of its Subsequent Vendors in the processing of Client Data.

15. Term and termination

Version 1.1 of this DPA takes effect on October 1, 2026. For a Client that accepts the Terms after that date, it takes effect on the date of acceptance. It stays in force for as long as Meo processes Client Data on behalf of the Client.

The provisions relating to confidentiality, to the destruction of data and to liability survive termination.

16. Amendments

Meo may amend this DPA to reflect legislative, regulatory or operational changes. In the case of a substantial amendment, Meo will inform the Client by email at least thirty (30) days before it takes effect.

If the Client does not accept the amendment, it may terminate the Services before the date on which the amendment takes effect.

17. Governing law and jurisdiction

This DPA is governed by the laws of Quebec and the laws of Canada applicable therein. Any dispute will be submitted to the exclusive jurisdiction of the courts of the judicial district of Québec.

18. Contact

For any question relating to this DPA or to the protection of Client Data:

Olivier Beaulieu

Privacy Officer

conformite@documeo.ca

1779 rue Careau, Québec, Canada, G1M 0C9

Version 1.1: effective October 1, 2026

Next scheduled review: October 1, 2027